Healthcare

MFA said yes. The attacker still got in.

Over three days in April, one phishing campaign hit more than 35,000 people across 13,000 organizations.

1 min readOriginally posted on LinkedIn

Over three days in April, one phishing campaign hit more than 35,000 people across 13,000 organizations. Healthcare was the most-targeted industry in it.

Here's the part that should get your attention: the people who got compromised did everything right. They typed their password. They approved the MFA prompt on their phone. The attacker still walked away with their mailbox.

The fake sign-in page wasn't after the password. It sat in the middle, passed everything through to the real Microsoft login in real time, and caught the session token that came back — the digital wristband that tells Microsoft "this person already proved who they are."

MFA is the bouncer checking ID at the door. The token is the wristband. Lift the wristband and you never have to talk to the bouncer again.

For a practice, that looks like someone reading your inbox quietly for a week, learning how billing runs, then emailing your billing company new wire instructions in your voice. Recovery isn't an afternoon. It's a frozen schedule and a very uncomfortable call with people who trusted you.

The fix is sign-in that can't be relayed: passkeys, Windows Hello, hardware keys. Nothing to type means nothing to hand over. Start with owners, billing, and anyone holding admin rights.

Worth a look before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions